search menu icon-carat-right cmu-wordmark

CERT Coordination Center

CERT/CC Vulnerability Notes Database


Published Public Updated ID CVSS Title
2026-05-20 2026-05-20 2026-05-20 VU#980487 Local privilege escalation in Linux Kernel (Dirty Frag)
2026-03-30 2026-03-26 2026-05-20 VU#221883 CrewAI contains multiple vulnerabilities including SSRF, RCE and local file read
2026-05-18 2026-05-18 2026-05-18 VU#777338 SGLang contains two remote code execution and one path traversal vulnerability
2026-05-11 2026-05-11 2026-05-12 VU#471747 dnsmasq contains several vulnerabilities, including attacker DNS redirect, privilege escalation, and heap manipulation
2026-05-11 2026-05-11 2026-05-11 VU#937808 Casdoor contains Arbitrary File Write vulnerability
2026-05-08 2026-05-08 2026-05-08 VU#260001 Linux kernel contains local privilege escalation vulnerability (Copy Fail)
2025-09-09 2025-09-09 2026-05-04 VU#461364 Hiawatha open-source web server has multiple vulnerabilities
2026-04-20 2026-04-20 2026-04-27 VU#915947 SGLang is vulnerable to remote code execution when rendering chat templates from a model file
2026-04-21 2026-04-21 2026-04-24 VU#414811 Terrarium contains a vulnerability that allows arbitrary code execution
2026-04-23 2026-04-23 2026-04-23 VU#748485 Unauthenticated configuration modification vulnerability in Central Office Services - Content Hosting Component
2022-08-11 2022-08-11 2026-04-22 VU#309662 Signed third party UEFI bootloaders are vulnerable to Secure Boot bypass
2026-04-22 2026-04-22 2026-04-22 VU#518910 Ollama GGUF Quantization Remote Memory Leak
2026-04-21 2026-04-21 2026-04-21 VU#890999 Radware Alteon has a reflected XSS vulnerability that can execute JavaScript in the host browser
2026-04-09 2026-04-09 2026-04-09 VU#536588 Multiple Heap Buffer Overflows in Orthanc DICOM Server
2026-03-12 2026-03-12 2026-04-07 VU#665416 SGLang (sglang) is vulnerable to code execution attacks via unsafe pickle deserialization

Sponsored by CISA.